[Control systems] ABB security advisory (AV26-942)
Canada's Cyber Centre relayed ABB advisory AV26-942 addressing CVE-2023-5778, a missing length check flaw in Freelance Controller industrial devices.
The Canadian Centre for Cyber Security published advisory AV26-942 on September 18, 2026, noting that ABB released a security advisory addressing vulnerabilities in the Freelance Controller product line, affecting multiple versions and models. The cited flaw is CVE-2023-5778, described as a missing length check. The Cyber Centre encourages users and administrators to review ABB's advisory and apply updates as they become available.
- Canadian Centre for Cyber Security advisory AV26-942, dated September 18, 2026.
- Covers ABB Freelance Controller, multiple versions and models.
- Addresses CVE-2023-5778, a missing length check vulnerability.
- Administrators urged to review ABB's advisory and apply updates.
Vulnerabilities mentionedAll →
- CVE-2023-57789.2—Length-parameter flaw enables unauthenticated DoS in ABB Freelance Controllerspublished · ABB Freelance Controller DCP
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-5778 | Length-parameter flaw enables unauthenticated DoS in ABB Freelance Controllers CVE-2023-5778 is an improper handling of length parameter inconsistency (CWE-130) in the communication handling of ABB Freelance Controllers, affecting the DCP, AC700, AC800, and AC900 controller families across Freelance releases from 2013 through 2019 SP1. A remote, unauthenticated attacker can send network traffic with inconsistent length parameters to the controller, triggering a fault with no user interaction or privileges required. Per the CVSS 4.0 vector (AV:N/AC:L/PR:N/UI:N with high availability and safety impact), the practical outcome is a crash or denial of service of the controller, and because these devices run industrial processes, the disruption can carry safety consequences in plants using Freelance as their DCS. All organizations running Freelance controllers on the affected releases are potentially exposed, though exploitation requires network reachability to the controller. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; ABB (the assigning CNA) has published the advisory. |
Full article67 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-942
Date: September 18, 2026
As of September 18, 2026, ABB published a security advisory to address vulnerabilities in the following product:
- Freelance Controller
- Multiple versions and models
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/control-systems-abb-security-advisory-av26-942